← Back
CWE-79

47,413 CVEs • Abstraction: Base • Likelihood of Exploit: High

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users.

JSON object

Loading...

CVEs (47,413)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jenkins
1Vboxwrapper
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by at...Show more
Jenkins vboxwrapper Plugin 1.3 and earlier does not escape the name and description of VBox node parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Selection Tasks
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulner...Show more
Jenkins Selection tasks Plugin 1.0 and earlier does not escape the name and description of Script Selection task variable parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Promoted Builds
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerabilit...Show more
Jenkins Promoted Builds (Simple) Plugin 1.9 and earlier does not escape the name and description of Promotion Level parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Multiselect Parameter
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability explo...Show more
Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Jdk Parameter
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attack...Show more
Jenkins JDK Parameter Plugin 1.0 and earlier does not escape the name and description of JDK parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Global Variable String Parameter
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Variable String parameters on views displaying parameters, resulting in a stored cross-site scripting (XS...Show more
Jenkins Global Variable String Parameter Plugin 1.2 and earlier does not escape the name and description of Global Variable String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Autocomplete Parameter
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complete String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS)...Show more
Jenkins Autocomplete Parameter Plugin 1.1 and earlier does not escape the name of Dropdown Autocomplete and Auto Complete String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Application Detector
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploi...Show more
Jenkins Application Detector Plugin 1.0.8 and earlier does not escape the name of Chois Application Version parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission.Show less
1Jenkins
1Rundeck
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Runde...Show more
Jenkins Rundeck Plugin 3.6.10 and earlier does not restrict URL schemes in Rundeck webhook submissions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to submit crafted Rundeck webhook payloads.Show less
1Jirafeau
1Jirafeau
Jun 17, 2026
May 17, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scripting. An attacker could upload image/svg+xml files containing JavaScript. When someone visits the Fi...Show more
The file preview functionality in Jirafeau < 4.4.0, which is enabled by default, could be exploited for cross site scripting. An attacker could upload image/svg+xml files containing JavaScript. When someone visits the File Preview URL for this file, the JavaScript inside of this image/svg+xml file will be executed in the users' browser.Show less
1Ipplan Project
1Ipplan
Jun 17, 2026
May 17, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Stored cross-site scripting (XSS) in admin/usermanager.php over IPPlan v4.92b allows remote attackers to inject arbitrary web script or HTML via the userid parameter.
1Arubanetworks
1Clearpass Policy Manager
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates...Show more
A remote reflected cross site scripting (xss) vulnerability was discovered in Aruba ClearPass Policy Manager version(s): 6.10.4 and below, 6.9.9 and below, 6.8.9-HF2 and below, 6.7.x and below. Aruba has released updates to ClearPass Policy Manager that address this security vulnerability.Show less
1Xarrow
1Xarrow
Jun 17, 2026
May 16, 2022
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
xArrow SCADA versions 7.2 and prior permits unvalidated registry keys to be run with application-level privileges.
1Xarrow
1Xarrow
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘edate’ of the resource xhisalarm.htm, which may allow an unauthorized attacker to execute arbitrary code.
1Xarrow
1Xarrow
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
xArrow SCADA versions 7.2 and prior is vulnerable to cross-site scripting due to parameter ‘bdate’ of the resource xhisvalue.htm, which may allow an unauthorized attacker to execute arbitrary code.
1Weintek
16Cmt Ctrl01 Firmware
Cmt Fhd FirmwareCmt G01 Firmware+13 more
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
The Weintek cMT product line is vulnerable to a cross-site scripting vulnerability, which could allow an unauthenticated remote attacker to inject malicious JavaScript code.
1Sir
1Gnuboard
Jun 17, 2026
May 16, 2022
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Gnuboard 5.55 and 5.56 is vulnerable to Cross Site Scripting (XSS) via bbs/member_confirm.php.
1Bootstrap Table
1Bootstrap Table
Jun 17, 2026
May 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session d...Show more
Bootstrap Tables XSS vulnerability with Table Export plug-in when exportOptions: htmlContent is true in GitHub repository wenzhixin/bootstrap-table prior to 1.20.2. Disclosing session cookies, disclosing secure session data, exfiltrating data to third-parties.Show less
1Clipr
1Clipr
Jun 17, 2026
May 16, 2022
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is...Show more
The Clipr WordPress plugin through 1.2.3 does not sanitise and escape its API Key settings before outputting it in an attribute, leading to a Stored Cross-Site Scripting issue even when the unfiltered_html capability is disallowedShow less
1Uleak Security Dashboard Project
1Uleak Security Dashboard
Jun 17, 2026
May 16, 2022
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could all...Show more
The ULeak Security & Monitoring WordPress plugin through 1.2.3 does not have authorisation and CSRF checks when updating its settings, and is also lacking sanitisation as well as escaping in some of them, which could allow any authenticated users such as subscriber to perform Stored Cross-Site Scripting attacks against admins viewing the settingsShow less